The risk has moved from the model to the ecosystem around it. A third-party skill can inherit an agent’s privileges, so a benign-looking add-on can become the place where credentials, files, or shell access are quietly turned against you.
CSO says frontier models like Claude Mythos and OpenAI GPT-5.5 are pushing vulnerability discovery toward industrial scale, and Unit 42 finds that most public agent skills diverge from their claims. The dangerous slice is smaller, but it includes multi-stage chains that can lead to credential theft, remote code execution, or silent data exfiltration without a novel exploit.